Privacy

Privacy policy

Last updated: July 2026

Who we are

źlab (operated by Zircular LLC) provides decision-governance services for physical assets. This policy explains how we collect, use, and protect personal information in connection with our website at zircular.io and our Operational Decision Stress Test service.

What we collect

Contact and account information. When you request access, create an account, or contact us, we collect your name, email address, company, and role.

Engagement data you provide. During an Asset Decision Review engagement, you may upload operational data about a physical asset — including BMS/SCADA telemetry, maintenance records, contracts, and unit economics. This data relates to your asset, not to you personally. To the extent it contains personal information (for example, names of personnel in uploaded documents), that information is subject to this policy.

Usage data. We collect information about how you interact with our website — pages visited, time spent, referring URLs, browser type, and IP address — through standard server logs and analytics tools.

How we use it

We do not sell your personal information. We do not use your data for advertising or share it with data brokers.

Operational data from engagements

Data you upload as part of an engagement (BMS/SCADA, contracts, telemetry, and similar records) is used solely to deliver that engagement. We treat it as confidential. We do not use engagement-specific operational data for any purpose other than producing your deliverable.

We may use aggregated, fully de-identified, and anonymized insights derived from completed engagements to improve our analytical methods — provided no information attributable to you, your company, or your asset can be reconstructed. We will not publish or share case studies based on your engagement without your explicit written consent.

Engagement data is retained for the period specified in your engagement agreement, and then deleted or returned per the terms of that agreement.

The źlab connector for AI assistants

You can connect źlab to your AI assistant as a connector (an MCP server at mcp.zircular.io). Access requires OAuth sign-in handled by our identity provider, which processes your email address and basic account data under its own privacy policy. We use your identity only to scope your submissions and results to your account.

What your assistant sends us. A decision case: the decision in your words, the asset (name, address, type), the decision stage, and optionally your proposed solution and descriptions of the evidence you hold. No documents are uploaded through the connector — evidence is described, not ingested. We never accept credentials or API keys, personal data about individuals, confidential document contents, or health, minors', or other regulated-category data: the case format gives such data no place, and submitting it is prohibited by contract.

What leaves our infrastructure. The analysis runs on our servers. To analyze a real asset, its name, address, and coordinates derived from them are sent as queries to public data services during the run — US federal data services (the Census geocoder and data APIs, EIA, NOAA, EPA, BLS, SEC EDGAR), OpenStreetMap, web-search services used to locate public records about the asset, and public web pages about the asset or its operator. No other part of your input — your decision text, proposed solution, or evidence descriptions — is shared with anyone. The connector requires your explicit authorization with every submission and will not run without it.

What we store and what we never log. We store governed run artifacts and an append-only event ledger for reliability and metrics. The ledger and telemetry contain only content hashes, a pseudonymous case id, coarse classes, job status, latency, and error class — never your decision text, the asset name or address, or any evidence content in plain text. We delete stored artifacts tied to your account on request.

We do not use your decision cases to train models. Every result carries a content hash and the exact framework version that produced it, so a result that circulates can be verified against what we actually emitted.

Service providers

We work with third-party service providers for cloud hosting, email delivery, payment processing, and analytics. These providers act as data processors on our behalf under contractual restrictions that prohibit them from using your data for their own purposes.

Your rights

California residents (CPRA). If you are a California resident, you have the right to: know what personal information we have collected about you and how it is used; request access to or a copy of your personal information; request correction of inaccurate information; request deletion of your personal information, subject to legal exceptions; opt out of sale or sharing of personal information (we do not sell or share); and not be discriminated against for exercising these rights.

All users. You may contact us at any time to access, correct, or delete your account information, or to ask questions about how your data is handled.

To exercise your rights, contact us at davidl@zircular.io. We will respond within 45 days of receiving a verifiable request.

Data security

We implement reasonable technical and organizational measures to protect personal information against unauthorized access, disclosure, or loss. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the service after a change constitutes acceptance of the updated policy.

Privacy inquiries

davidl@zircular.io